Database/Firmware, BMC & network fabric
Linux RDMA/srpt: failed multi-buffer descriptor setup leaves stale counters and a dangling rw_ctxs pointer
Impact
When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys the RDMA contexts but leaves n_rw_ctx and n_rdma set and rw_ctxs dangling. Later send-queue credit accounting in srpt_queue_response() or srpt_write_pending() then subtracts the wrong number of credits, and a freed pointer remains reachable. This only matters on nodes that export SRP targets over InfiniBand/RoCE - a storage or fabric-attached node in a GPU cluster, not a plain compute node. Reaching it requires a client that can open an SRP session to the target and drive descriptor allocation to failure; NVD's 9.8 network score is the automated kernel-CNA default and overstates how exposed a typical fleet is, since the SRP target fabric is usually a trusted storage network.
Who can reach it
A host that can establish an SRP session with the target over the RDMA fabric. Only nodes running the srpt target module are affected; if ib_srpt is not loaded, there is no exposure.
What to do
Take the stable-kernel fix on affected nodes (five stable branches carry it) and reboot, or unload/reload ib_srpt if your kernel packaging allows it - in practice the SRP target has to be taken out of service either way. No vendor-supplied mitigation short of not running the SRP target.
References
Related entries
- Cisco Nexus 9000: unauthenticated remote code execution as root via Silicon One ports in the default L3 VRFCVE-2026-20212 · Cisco Nexus 9000 NX-OS Silicon One integration (S1HAL, TCP 43210/43211)Critical
- Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handling: nvmet_tcp_build_pdu_iovec() walks pastCVE-2026-23112 · Linux kernel nvmet-tcp - PDU iovec construction and H2C Transfer Tag handlingCritical
- Linux kernel (drivers/infiniband/core): The iWARP connection manager returns work items to a free list while the sameCVE-2026-45898 · Linux kernel (drivers/infiniband/core)Critical
- Linux kernel - RDMA/rxe memory region translation, drivers/infiniband/sw/rxe/rxe_mr.c: Rxe mishandles memory regionsCVE-2026-46325 · Linux kernel - RDMA/rxe memory region translation, drivers/infiniband/sw/rxe/rxe_mr.cCritical
- Linux kernel NVMe-oF TCP target (nvmet-tcp, unpropagated PDU iovec build errors): Nvmet_tcp_build_pdu_iovec() detectsCVE-2026-52989 · Linux kernel NVMe-oF TCP target (nvmet-tcp, unpropagated PDU iovec build errors)Critical
- Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.c: The iSER targetCVE-2026-53176 · Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.